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AMENDMENTS TO THE CLAIMS: 

This listing of claims will replace all prior versions, and listings, of claims in the 
application: 

LISTING OF CLAIMS: 

1 . (Currently Amended) A method for identifying the source of an event in a 
computer network, comprising the steps of: 

associating an identifier tag with an event occurring within the computer 
network, wherein the identifier tag uniquely identifies at least one collection computer 
monitoring the event based on a domain name; 

receiving, in at least one management computer, information from the at least 
one collection computer that includes the identifier tag; 

deriving, by the at least one management computer, an identification of the at 
least one collection computer from the identifier tag based on the domain name; and 

identifying to a user the source of the event using the identification of each the 
at least one collection compute r, the at least one collection computer being at least 
one of a collection computer and a group of collection computers . 

2. (Original) The method of claim 1 , wherein the identifier tag is a name 
of the at least one collection computer. 

3. (Original) The method of claim 1 , wherein the step of deriving 
comprises the step of: 



Attorney's Docket No. 10007592-1 
Application No. 09/838.205 

Page 3 



maintaining within the at least one management computer a database of 
identification information associated with identifier tags. 

4. (Original) The method of claim 1 . wherein the step of identifying 
comprises the step of: 

displaying to the user the identification of the at least one collection computer 
and a network address of a network element that generated the event. 

5. (Original) The method of claim 1 , wherein the step of identifying 
comprises the step of; 

mapping each collection computer to a group of collection computers using 
the identifier tag; and 

identifying to the user the source of the event using the group of collection 
computers and a network address of a network element that generated the event. 

6. (Previously Presented) The method of claim 1, further comprising the 
steps of: 

managing, by the collection computer, at least one network object; and 
resolving, by the collection computer, a network address of each network 

object into a resolved network address included in the information received at the at 

least one management computer. 

7. (Currently Amended) A system for identifying the source of an event in 
a computer network, comprising: 
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a plurality of collection computers, wherein an identifier tag uniquely identifies 
each collection compute r or group of collection computers based on a domain name, 
and wherein the identifier tag is associated with an event occurring within the 
computer network; 

at least one management computer for receiving information from the plurality 
of collection computers that includes the identifier tag, wherein each management 
computer derives an identification of each collection compute r or group of collection 
computers from the identifier tag based on the domain name; and 

means for identifying to a user the source of the event using the identification 
of each collection compute r or group of collection computers . 



